Business intelligence (BI) platform provider Metabase has disclosed a zero-day SQL Injection vulnerability, warning that customers’ sensitive credentials, tokens, API keys, and other data may have been exposed.
The Metabase vulnerability revealed on August 6, designated CVE-2026-72898, is identified as critical, with a severity score of 10, the highest possible rating. It is present in versions 1.58 and up.
“You don’t see a perfect 10/10 on CVSS often, but when you do, be worried,” noted David Shipley, CEO of Beauceron Security. SQL injection is “old school and painful, as there’s now working proof of concept exploit code.”
‘Unmitigated, raw’ database access
Metabase is an open-source BI tool that customers can connect to popular databases, including Databricks, MongoDB, Oracle, Snowflake, Amazon, BigQuery, and many others. They can use the platform to access analytics, query and visualize data, and build dashboards, among other actions.










